Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers
ID: 918e97b6-427a-5486-9ff5-b9996357a1a9
STIX ID: report--918e97b6-427a-5486-9ff5-b9996357a1a9
Feed Name: HackRead
Threat Score
Darktrace observed a campaign (18 March 2026) using a misconfigured Jenkins scriptText endpoint to gain RCE and distribute a cross-platform DDoS botnet that targets Valve Source Engine game servers; the report documents delivery artifacts (w.exe, bot_x64.exe), a single C2 IP (103.177.110.202), persistence techniques (env var dontKillMe, renaming to system-like processes), and attack modes that overload game server responses and specific ports (27015, 53, 123).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
